A federal investigation has revealed a malware campaign that used video games to infect over 8,000 devices and steal cryptocurrency. The operation reportedly ran from May 2024 through February 2026, targeting people who downloaded infected games.
Hidden Malware in Games
Court documents describe eight games that contained malicious code designed to collect passwords, wallet credentials, browser data, and other sensitive information. After users installed the titles, the malware allegedly searched for cryptocurrency wallet details. Authorities estimate that roughly 80 wallets were accessed and drained as a result.
The games mentioned in the complaint include BlockBlasters, Chemia, Dashverse or DashFPS, Lampy, Lunara, PirateFi, and Tokenova. Although investigators did not name the distribution platform, details point to Steam. The FBI is gathering information from anyone who may have downloaded those titles. Security researchers previously flagged wallet-stealing malware in PirateFi before Steam removed it.
How the Campaign Worked
According to the complaint, the malware was promoted through social media channels like Discord, Telegram, X, and LinkedIn. Automated bots reportedly scanned online communities to identify people with significant cryptocurrency holdings. Those individuals then received targeted messages encouraging them to install the infected games.
Once on a device, the malware looked for login credentials, wallet keys, and authentication data. Members of the alleged conspiracy then reviewed the stolen files and picked wallets they could access and empty.
Digital Trail Leads to Suspect
Prosecutors accuse Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, of helping fund and promote the malware operation. Encrypted Signal conversations allegedly show Wilkins using the handle “Sibel.eth” while talking to the suspected primary developer. Those chats included discussions about buying a $10,000 remote access trojan and planning campaigns to drain victims’ wallets.
Bitcoin transactions linked to the operation eventually led investigators to Bitrefill, a service that converts cryptocurrency into gift cards. More than 150 digital gift cards were allegedly bought with stolen crypto, mostly redeemed for Uber Eats. Subpoenaed records connected deliveries to Wilkins’ university addresses and his home in South Florida.
When agents executed a search warrant, they recovered electronic devices and three cryptocurrency wallet seed phrases, including one tied to a Monero wallet. Transaction records show that Wilkins allegedly sent or received about $382,000 in cryptocurrency.
He now faces one count of conspiracy to obtain computer information for private financial gain. If convicted, he could be sentenced up to 10 years in prison.
![]()

